<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;how to cancel the data source&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412494#M173573</link>
    <description>&lt;P&gt;i configure it through "add data"--&amp;gt; "monitor" --&amp;gt; local performance monitoring&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jan 2019 07:23:16 GMT</pubDate>
    <dc:creator>johnsmithcy</dc:creator>
    <dc:date>2019-01-18T07:23:16Z</dc:date>
    <item>
      <title>"how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412492#M173571</link>
      <description>&lt;P&gt;the host monitoring keep fetching the CPU data.&lt;BR /&gt;
 I want to cancel the date source&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 06:59:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412492#M173571</guid>
      <dc:creator>johnsmithcy</dc:creator>
      <dc:date>2019-01-18T06:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412493#M173572</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412493#M173572</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-18T07:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412494#M173573</link>
      <description>&lt;P&gt;i configure it through "add data"--&amp;gt; "monitor" --&amp;gt; local performance monitoring&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412494#M173573</guid>
      <dc:creator>johnsmithcy</dc:creator>
      <dc:date>2019-01-18T07:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412495#M173574</link>
      <description>&lt;P&gt;Hi @johnsmithcy,&lt;/P&gt;

&lt;P&gt;you can use the below command in CLI:-&lt;/P&gt;

&lt;P&gt;sourcetype=my_sourcetype | delete&lt;BR /&gt;
For more details check this &lt;A href="http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk"&gt;http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412495#M173574</guid>
      <dc:creator>MoniM</dc:creator>
      <dc:date>2019-01-18T07:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412496#M173575</link>
      <description>&lt;P&gt;thank you. any graphical interface method?&lt;BR /&gt;
I am using windows version&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412496#M173575</guid>
      <dc:creator>johnsmithcy</dc:creator>
      <dc:date>2019-01-18T07:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412497#M173576</link>
      <description>&lt;P&gt;Then try to find it under settings-&amp;gt; data inputs -&amp;gt; local Windows or local perfomance monitoring &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; than click delete or disable&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 07:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412497#M173576</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-18T07:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412498#M173577</link>
      <description>&lt;P&gt;Okay, so you can delete your sourcetype by following below steps:-&lt;BR /&gt;
1. login to your splunk instance and goto settings&lt;BR /&gt;
2.  In data, goto sourcetypes and search for your sorectype(which you created for your "CPU" input).&lt;BR /&gt;
3.  delete that sourcetype.&lt;/P&gt;

&lt;P&gt;Let me know if it works.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 08:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412498#M173577</guid>
      <dc:creator>MoniM</dc:creator>
      <dc:date>2019-01-18T08:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: "how to cancel the data source"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412499#M173578</link>
      <description>&lt;P&gt;it works, thx&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 08:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/quot-how-to-cancel-the-data-source-quot/m-p/412499#M173578</guid>
      <dc:creator>johnsmithcy</dc:creator>
      <dc:date>2019-01-18T08:54:14Z</dc:date>
    </item>
  </channel>
</rss>

